Travel Safely RSA (“we”, “our”, “us”) operates the Travel Safely RSA mobile application and the Business Portal at www.travelsafelyrsa.co.za (“the website”). We are committed to protecting the personal information of all users and business registrants in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). This policy explains what data we collect, why we collect it, how it is used, and your rights regarding that data.
1. Information We Collect
From app users:
- Email address — required to create and authenticate your account.
- Display name / username — optional; auto-generated if not provided. Never your real name unless you choose to set one.
- Location data — GPS coordinates, speed, and heading. During an active in-app navigation session, the Google Maps Navigation SDK continuously tracks your real-time position to provide turn-by-turn guidance, rerouting, and hazard alerts — this may briefly continue in the background if your screen locks or you switch to another app mid-drive, so voice guidance isn't interrupted. Outside of an active navigation session, your location is accessed only when you actively add a safety marker or search for nearby places. We do not track your location in the background when no navigation session is active, or after the app has been closed.
- User-generated content — comments, marker descriptions, votes, ratings, reviews, and place suggestions you submit. A place suggestion consists of a business/place name, category and location (selected from Google Places) together with your account identifier and email address. If an administrator approves it, the name, category and location become a publicly visible “community” listing in the app; your email is not shown publicly.
- Content reports and blocks — if you report a listing, we store the listing reference, the reason you select, and your account identifier. If you choose to hide a contributor, we store that contributor’s identifier against your account so their community listings stop showing to you.
- Saved routes — when you save a route, we store its start and end points, the road path (route geometry) and a coarse location index derived from it, and whether you have switched on hazard alerts for that route. This is used to notify you when a caution, unsafe, accident or roadworks marker is later added on that route.
- Push notification token — an anonymous device token issued by Firebase Cloud Messaging, used only to deliver notifications you have asked for (such as route hazard alerts). Removed from your account when you sign out on that device.
- Saved places — establishments and guide places you bookmark, kept against your account so you can find them again.
- Listing view counts — when you open a business listing, an anonymous view is counted against that listing so the business owner can see how many travellers viewed it. This is not linked to your identity in any report shown to the business.
- Device diagnostics — anonymous crash reports including device model, OS version, and app state. No personally identifiable information is attached to these reports.
From business registrants (Business Portal):
- Contact details — contact person name, business email address, and phone number provided during registration.
- Business information — business name, category, physical address, website or social media URL, opening hours, and business description.
- Business photos — images submitted during the onboarding process, stored on Cloudinary.
- Subscription information — subscription status, trial start and end dates, and billing correspondence. We do not store payment card details.
- Business login credentials — a Firebase Authentication account is created on your behalf when your listing goes live. Your credentials are sent to you by email.
2. How We Use Your Information
- To authenticate your account and maintain session security.
- To display and improve community safety markers on the map.
- To calculate reporter reputation scores and marker trust scores.
- To match newly added hazard markers against routes you have chosen to watch, and send you a push notification when one falls on such a route.
- To review, publish, moderate and remove community place suggestions, and to act on content reports.
- To display City Guide place listings and enhanced business listings in the app.
- To let you save places and revisit them from "My Saved Places".
- To show business owners aggregate view and save counts for their own listing.
- To manage business listing status (trial, active, lapsed) and notify businesses of upcoming subscription renewals or expiry.
- To allow business owners to log in and manage their listing details, photos, and opening hours.
- To detect, investigate, and prevent fraudulent or abusive activity.
- To respond to support requests and enquiries submitted via the Business Portal or email.
- To send critical service notifications (e.g. account security alerts, subscription renewal reminders).
3. Lawful Basis for Processing (POPIA)
- Contract — processing necessary to provide the service you have requested (app account, business listing).
- Legitimate interest — improving service quality, preventing abuse, and maintaining platform security.
- Consent — where you have actively chosen to submit optional information such as a display name or business photos.
4. Data Sharing
We do not sell, rent, or trade your personal information to any third party. We use the following trusted sub-processors, each bound by their own privacy frameworks:
- Google Firebase — authentication, Firestore database, and anonymous crash analytics (Crashlytics).
- Cloudinary — storage and delivery of business listing photos.
- Google Maps Platform — map rendering, geocoding, place search, and points-of-interest data displayed in the app. When you suggest a place, your search text is sent to the Google Places API to resolve the place’s name, address and coordinates.
- Firebase Cloud Messaging (Google) — delivery of push notifications you have opted into, such as route hazard alerts.
- Google Maps Navigation SDK — powers in-app turn-by-turn navigation. During an active navigation session, your real-time GPS position, speed, heading, and route are processed by Google’s navigation engine, subject to Google’s Privacy Policy.
- Vercel — hosting of the Business Portal website, and lightweight backend processing. When a hazard marker is added, the marker’s location is checked against watched routes on a Vercel function so the relevant notifications can be sent; it also processes place-suggestion moderation actions. Vercel may log standard web server access data (IP address, browser type, page visited) for security and performance monitoring.
Business listing information (name, address, contact details, photos, hours, description) that you submit as a business registrant is displayed publicly within the app and is accessible to all app users. Place-suggestion content that is approved (place name, category and location) is likewise displayed publicly. Please only submit information you are comfortable being publicly visible.
5. Data Retention
- App user accounts — retained for as long as your account is active. You may request deletion at any time by contacting us or using the Delete Account function in the app.
- Safety markers — may remain visible after account deletion, as they serve a community safety purpose. Contact us to request removal.
- Saved places and saved routes — retained while your account is active; removed if you delete them or delete your account.
- Route hazard alerts — the in-app alert history is retained while your account is active and removed on account deletion.
- Place suggestions — an approved suggestion becomes a community listing and follows the business-listing retention rules above. A rejected or pending suggestion is retained for up to 12 months for moderation record-keeping, then deleted.
- Content reports — retained for up to 12 months to support moderation and repeat-abuse detection.
- Business listings (active) — retained for the duration of your trial or paid subscription and for a reasonable period thereafter to allow for reactivation.
- Business listings (lapsed) — enhanced listing data (photos, contact details, hours) is removed from public view within 30 days of a subscription lapsing. A basic unclaimed record may remain.
- Business registration correspondence — retained for up to 2 years for record-keeping purposes.
- Crash and analytics data — retained by Firebase for up to 14 months.
6. Your Rights Under POPIA
As a data subject under the Protection of Personal Information Act 4 of 2013, you have the right to:
- Be informed about the collection and use of your personal information.
- Access the personal information we hold about you.
- Request correction of inaccurate or outdated information.
- Request deletion (“erasure”) of your personal information, subject to our legal retention obligations.
- Object to or restrict the processing of your personal information.
- Lodge a complaint with the Information Regulator of South Africa if you believe your rights have been infringed.
To exercise any of these rights, contact us at hello@travelsafelyrsa.co.za. We will respond within 30 days.
7. Security
We take reasonable and appropriate technical and organisational measures to protect your personal information, including Firebase security rules, role-based access controls, and encrypted HTTPS/TLS connections for all data in transit. Business login credentials are transmitted only via email to the address you registered with. No method of electronic storage or transmission is 100% secure; we encourage you to use a strong, unique password.
8. Children
Travel Safely RSA is not directed at persons under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, please contact us immediately and we will take steps to delete it.
9. Cross-Border Transfers
Your data may be processed on servers located outside South Africa, including in the United States (Google Firebase, Cloudinary, Google Maps Platform, Vercel). These transfers are subject to the privacy frameworks of the respective service providers, which provide comparable protection to POPIA.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or the law. We will notify app users of material changes via an in-app notification. Business registrants will be notified by email. The revised policy will always be posted at this address with an updated date. Continued use of our services after the effective date constitutes acceptance.